Container image vulnerability scanning: full steps for Trivy CI gates

Full steps for container image vulnerability scanning: scan images locally with Trivy, block CRITICAL in CI, and roll out by registry. Covers base-image noise, exception TTL, and exit-code conventions for an enforceable image release gate.